open-emr
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 218 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 9, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics
OpenEMR 7.0.1 Authentication Brute Force Mitigation Bypass
OpenEMR has a Privilege Escalation that Allows a Low-Level User to View Admin-Only Data
OpenEMR has IDOR in Patient Notes Web UI allows unauthorized note access/modification
OpenEMR Missing Authorization in Procedure Order AJAX Deletion Handler
OpenEMR has Improper ACL On Import/Export Popup
OpenEMR's Missing Authorization in show-signature.php Allows Portal Patients to Read Staff Signatures
Reflected XSS via Unescaped contextName Parameter in Custom Template Editor
OpenEMR has Stored XSS in CCDA Preview via Unsanitized linkHtml Attributes
OpenEMR has IDOR in Portal Payment Page that Allows Cross-Patient Record Access
Monitor open-emr in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.